
France's DGFiP leak exposed personal data of 678,437 taxpayers, including 27K with incomes over €100K. Combined with rising wrench attacks across the country, the breach raises physical security risks for crypto holders.
France is confronting a large-scale data breach at the General Directorate of Public Finances. French media reported that a cyberattack exposed personal and financial information belonging to 678,437 taxpayers. The compromised data includes names, dates of birth, addresses, telephone numbers, email addresses, and income declarations.
Nearly 27,000 of those affected declared at least €100,000 in income. Another 386 reported more than €1 million, and eight exceeded €10 million. The breach does not prove any of those individuals own cryptocurrency. Security researchers said combining tax records with public blockchain activity and social media profiles helps criminals build more precise targets.
The timing adds to the concern. Physical attacks against crypto holders are becoming more frequent across France. CertiK recorded 52 verified wrench attacks worldwide in the first half of 2026, with France accounting for 33 of them. The security firm also noted a sharp increase in home invasions tied to crypto theft. Chainalysis documented 46 physical attacks against crypto holders in the first half of 2026, with more than $30 million stolen overall.
French Interior Minister Laurent Nuñez promised to strengthen security for crypto-sector actors after the surge in incidents. He said authorities recorded 77 cases of violence tied to cryptocurrency, BFMTV reported. In August, police arrested four men in Marseille who were holding two women hostage while demanding crypto.
For crypto users, the lesson is not that self-custody fails. Non-custodial wallets keep private keys outside centralized databases, reducing the consequences of a conventional account breach. The bigger vulnerability is often the information surrounding ownership: names, addresses, phone numbers, and purchase records.
A separate August breach involving Trezor's logistics provider ShipMonk reinforces that point. Nearly 14,000 customers were affected, with names, addresses, phone numbers, and emails exposed. Trezor said its own systems, devices, and wallet security were not compromised.
The overlap between data breaches and physical crypto crime strengthens the case for privacy-conscious security practices, analysts said. Users can reduce unnecessary personal-data exposure, separate public identities from wallet activity where practical, and treat unsolicited messages requesting wallet credentials as potential phishing attempts. Blockchain transparency remains useful for auditing transactions, while privacy-preserving technologies can limit how easily financial activity connects to a real-world identity.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.